--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-9671
2009-09-16 20:03:26
--------------------------------------------------------------------------------

Name        : xmp
Product     : Fedora 10
Version     : 2.7.1
Release     : 1.fc10
URL         : https://xmp.sourceforge.net/
Summary     : A multi-format module player
Description :
The Extended Module Player is a modplayer for Unix-like systems that plays
over 80 mainstream and obscure module formats from Amiga, Atari, Acorn,
Apple IIgs and PC, including Protracker (MOD), Scream Tracker 3 (S3M), Fast
Tracker II (XM) and Impulse Tracker (IT) files.

--------------------------------------------------------------------------------
Update Information:

Update to latest stable release. Multiple bugfixes and memory leak fixes. Fixes
for buffer overflows in DTT and OXM loaders.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Sep 14 2009 Dominik Mierzejewski  2.7.1-1
- updated to 2.7.1
- fixes CVE-2007-6731 (rhbz#523138) and CVE-2007-6732 (rhbz#523147)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #523138 - CVE-2007-6731 xmp: Multiple buffer overflows in OXM decoder
        https://bugzilla.redhat.com/show_bug.cgi?id=523138
  [ 2 ] Bug #523147 - CVE-2007-6732 xmp: Buffer overflow in DTT file loader
        https://bugzilla.redhat.com/show_bug.cgi?id=523147
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update xmp' at the command line.
For more information, refer to "Managing Software with yum",
available at .

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------

_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-package-announce

Fedora 10 Update: xmp-2.7.1-1.fc10

September 24, 2009
Update to latest stable release

Summary

The Extended Module Player is a modplayer for Unix-like systems that plays

over 80 mainstream and obscure module formats from Amiga, Atari, Acorn,

Apple IIgs and PC, including Protracker (MOD), Scream Tracker 3 (S3M), Fast

Tracker II (XM) and Impulse Tracker (IT) files.

Update Information:

Update to latest stable release. Multiple bugfixes and memory leak fixes. Fixes for buffer overflows in DTT and OXM loaders.

Change Log

* Mon Sep 14 2009 Dominik Mierzejewski 2.7.1-1 - updated to 2.7.1 - fixes CVE-2007-6731 (rhbz#523138) and CVE-2007-6732 (rhbz#523147)

References

[ 1 ] Bug #523138 - CVE-2007-6731 xmp: Multiple buffer overflows in OXM decoder https://bugzilla.redhat.com/show_bug.cgi?id=523138 [ 2 ] Bug #523147 - CVE-2007-6732 xmp: Buffer overflow in DTT file loader https://bugzilla.redhat.com/show_bug.cgi?id=523147

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update xmp' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
Name : xmp
Product : Fedora 10
Version : 2.7.1
Release : 1.fc10
URL : https://xmp.sourceforge.net/
Summary : A multi-format module player

Related News